Описание
Unrestricted file upload vulnerability in Apache Tomcat 7.x before 7.0.40, in certain situations involving outdated java.io.File code and a custom JMX configuration, allows remote attackers to execute arbitrary code by uploading and accessing a JSP file.
Релиз | Статус | Примечание |
---|---|---|
devel | not-affected | |
esm-apps/xenial | not-affected | |
esm-infra-legacy/trusty | not-affected | 7.0.52-1ubuntu0.1 |
lucid | DNE | |
precise | ignored | end of life |
precise/esm | DNE | precise was needs-triage |
trusty | not-affected | 7.0.52-1ubuntu0.1 |
trusty/esm | not-affected | 7.0.52-1ubuntu0.1 |
upstream | released | 7.0.40-1 |
utopic | not-affected |
Показывать по
Ссылки на источники
EPSS
6.8 Medium
CVSS2
Связанные уязвимости
Unrestricted file upload vulnerability in Apache Tomcat 7.x before 7.0.40, in certain situations involving outdated java.io.File code and a custom JMX configuration, allows remote attackers to execute arbitrary code by uploading and accessing a JSP file.
Unrestricted file upload vulnerability in Apache Tomcat 7.x before 7.0.40, in certain situations involving outdated java.io.File code and a custom JMX configuration, allows remote attackers to execute arbitrary code by uploading and accessing a JSP file.
Unrestricted file upload vulnerability in Apache Tomcat 7.x before 7.0 ...
Уязвимость программного обеспечения Apache Tomcat, позволяющая удаленному злоумышленнику нарушить конфиденциальность, целостность и доступность защищаемой информации
EPSS
6.8 Medium
CVSS2